CVE-2026-78886: liketrek TREK Public Journey Photo Proxy journey-public.controller.ts path traversal
A security flaw has been discovered in liketrek TREK up to 3.0.22. This affects an unknown function of the file server/src/nest/journey/journey-public.controller.ts of the component Public Journey Photo Proxy. Performing a manipulation results in path traversal. The attack can be initiated remotely. The attack's complexity is rated as high. The exploitability is reported as difficult. Upgrading to version 3.1.0 mitigates this issue. It is advisable to upgrade the affected component.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
liketrek TREK Public Journey Photo Proxy (file server/src/nest/journey/journey-public.controller.ts)to a version that resolves this vulnerability.Fixed in 3.1.0
Event History
Frequently Asked Questions
Which deployments are affected?
The issue affects the Public Journey Photo Proxy component in liketrek TREK versions up to 3.0.22. Version 3.1.0 is identified as mitigating the issue.
Can this be exploited without authentication or user interaction?
The provided vector indicates no privileges and no user interaction are required, and the attack can be initiated remotely. Exploitation is rated high complexity and reported as difficult.
What is the impact if exploitation succeeds?
The reported impact is limited to confidentiality, with low confidentiality impact and no stated integrity or availability impact. The flaw is categorized as path traversal.